An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104019 | third party advisory vdb entry |
http://www.securitytracker.com/id/1040807 | third party advisory vdb entry |
https://bugs.php.net/bug.php?id=76249 | patch vendor advisory issue tracking |
https://www.debian.org/security/2018/dsa-4240 | third party advisory vendor advisory |
https://www.tenable.com/security/tns-2018-12 | third party advisory |
https://usn.ubuntu.com/3646-1/ | third party advisory vendor advisory |
http://php.net/ChangeLog-5.php | patch vendor advisory |
http://php.net/ChangeLog-7.php | patch vendor advisory |
https://security.gentoo.org/glsa/201812-01 | third party advisory vendor advisory |
https://security.netapp.com/advisory/ntap-20180607-0003/ | third party advisory |
https://lists.debian.org/debian-lts-announce/2018/06/msg00005.html | third party advisory mailing list |
https://access.redhat.com/errata/RHSA-2019:2519 | vendor advisory |